Description
- Product Information
CardOS V4.4 offers the following general features:
ISO/IEC 7816 compatible commands
“Command chaining” in accordance with ISO/IEC 7816-4, for example for implementing multi-stage processes or for the transmission of a related data stream that is too large for the data field of an individual command
A dynamic, flexible file system based on ISO/IEC 7816-4 with the following characteristics:
Number of files and folders with any depth of nesting limited only by the storage capacity of the chip
Short File IDs
Dynamic memory management for optimal utilization of the available EEPROM
Protection mechanisms against EEPROM defects and power failure
Support of CV (card verifiable) certificates
Extraction and use of the public key directly from the certificate
Verification of certificates and certificate chains
Standards interface for external public key certificate services using the separately available CardOS API Cryptography Interface (Microsoft CSP / Base CSP & PKCS#11)
Compatibility with the most important international standards provides long-term security for integration in standardized environments (readers, applications, etc.)
Expandability of the operating system with the subsequent addition of software packages, ensuring protection of your investment
Automatic integrity protection of all active software packages on the chip prevents the use of corrupt software
Cryptographic Functions
CardOS V4.4 provides a large number of cryptographic functions and algorithms, such as
Creation and verification of digital signatures
Encryption and decryption
Creation/verification of MACs
Calculation of cryptographic hash values (SHA-1)
SHA-2 package
Fast symmetric algorithms due to the hardware DES accelerator o Triple DES (CBC) and DES (ECB, CBC) with ISO padding o MAC and retail MAC with ISO or ANSI padding
Asymmetric algorithms
Up to 2048 bit RSA based on the CRT with and without a specified public exponent
PKCS#1-BT1, PKCS#1-BT2 or leading zeroes padding
Internal and external key generation
Flexible derivation of session keys
The PROOF OF CORRESPONDENCE command enables checking the association of an RSA public key in the command data field with a private key on the chip
General Integrity Protection for Responses (GIPR) for high security applications: Secure messaging with integrity protection of the command response regardless of whether the response data field is empty
True random number generator
- Standard Features
Hardware Platform:
CardOS V4.4 is available with the SLE66CX680PE hardware platform (chip) from Infineon as wafer, module (M5.1), ID-1 or ID-000 card and as DSO-8 package.